Live data from Hacker News

Check Your IP Reputation Score

ipdata.co

61–70 of 78 posts

Re: Check Your IP Reputation Score

#61

Earlier quoted context omitted.

> Legit website users just never use VPN or Tor for anything. You are wrong. I use that and a minority of legit people also do. The problem with your type of thinking is that you are only thinking in terms of what the population majority is doing and how they are behaving - lumping the minority of privacy conscious user in with all kinds if malicious actors. Basically the type of thinking that leads to all kinds of d…

No, it is based on my web logs across my websites. I have never had a single purchase come through a VPN or Tor node. I have never had a legitimate customer or personal enquiry come through a VPN or Tor node. 100% of VPN and Tor access to my websites have all been hacking and spam attempts. I have spent the last few months fighting spam & hacking attempts in detail - primarily from a Russian & Chinese exploit botnet…

> I used to think VPNs and Tor were a good thing (about a decade ago). My mind has been changed by looking at the quantitative data I have collected.

They are a good thing! Your mind has changed because your work has changed and you now are solely confronted with the negative aspects of using VPNs and Tor.

I'm pretty sure if you would have worked at an NGO on free speech you'd still be convinced of VPNs and Tor.

From you are staying the solution îs probably to increase the number of legitimate and responsable VPN/Tor users so that sysadmins don't automatically associate VPN/Tor with criminal usage patterns.

Re: Check Your IP Reputation Score

#62

Earlier quoted context omitted.

No, Cloudfare often just blocks you. And if it doesn't, do you think that is a better solution, solving a captcha every 5 minutes? Just try using Google from behind a serious VPN provider, see how that works for you. Also, what is your opinion on geoblock, do you think that is a good thing? It seems you are one of the company's representatives that has never in his life consistently used a VPN or Tor, so you don't ev…

To clarify, showing captchas is what a number of our customers do and I doubt they do it as aggressively as google. Geoblocks are unfortunately often necessary to comply with the law or contractual obligations eg. media streaming.

> I doubt they do it as aggressively as google.

While I would like to believe you the problems is that until there is a law on how much you can pester people with captchas (and you basically can pester them into oblivion) , privacy-conscious people are simply at the mercy of the sysadmin deciding for them how usable the company service is made. Which is a decidedly bad state of affairs, since he could simply wake up at any day, whip up Google-style captcha-ing and as a VPN user you simply would have no option for recourse :(

Re: Check Your IP Reputation Score

#63

Earlier quoted context omitted.

What's your problem with VPN users? Are you some kind of voyeur that likes to snoop in other people's private business? Where I go in the internet is my business alone, just like were I go outside my house. And having an online version of China's social credit tracking me online to see if I behave is not a good thing. You are providing a service that is actively diminishing (already brittle) internet privacy and I ha…

IMO VPN services that don't defeat geolocation like Apple's Private Relay, the Google One VPN service and Cloudflare Warp are a good compromise for privacy. This is because they allow businesses to provide their services without breaking the law eg. gambling is legal in some states and illegal in others, betting services need to distinguish/target users accordingly. Insurance providers might only be licensed in certa…

> VPN services that don't defeat geolocation like Apple's Private Relay, the Google One VPN service

TL;DR these VPN offerings don't provide privacy since we are merely exchanging who is doing the surveillance.

Long version: The problem with these are that instead of now denying a service to privacy-conscious users, these users are being profiled big tech companies that can afford to do more sophisticated things like track you across the internet using trackers and browser fingerprinting and thus don't need to rely on IP addresses. By profiling you they are themselves able to guarantee geolocation or to kick you permanently out of their VPN if you violate their arbitrary ToS.

And that they are profiling you is totally making sense too: Otherwise how would they be able to keep any malicious activity at bay.

> legitimate reasons

Yes, these are legitimate reasons. But does the need of a number of profit-based tech companies outweigh the need of society for privacy?

I doubt it! Since it doesn't seem fair that everyone must suffer for the benefit of a few.

The entire problems is made more complicated by:

1) lawmakers that don't understand that you simply cannot perfectly replicate.

It particular the need for geoblocking shows how arbitrary laws even are, if the same thing is lawful in one state but not the next.

Thus it seems contrived to do surveillance on everyone just so that a few companies who insist on having an internet presence can emulate physical geopresence.

There should be a law that states that if it takes too much of a toll on privacy to emulate physical behavior, you should be forbidden to seek to emulate it.

2) the fact that you can put an exact number of how much money you save as a business by using such scores, but you cannot put an exact number on how detrimental privacy loss is, since thst evolves on a very slow timescale. The latter only becomes visible really late, like a silent but terminal disease that barely in the very last stages begins to show itself: For example, when you reach China-style surveillance. Only then most people ask themselves: How did we get there?

To conclude: I don't particularly blaim your service for that since you are simply acting within a web of incentives and probably your livelihood depends on it - and if that is the case you can't possibly be expected to make an obiective decision (sorry if I was a bit harsh in this entire back-and-forth). Though if I were running such a company at least I'd make sure to donate some funds to non-profits that promote privacy and the use of VPNs/Tor for everyone - somewhat similar to CO2 reduction certificates that CO2 emitters buy.

Re: Check Your IP Reputation Score

#64

Earlier quoted context omitted.

No, if your reputation is really bad you'll probably just be shown a captcha.

Not even close. PayPal, Twitter, Facebook, Discord, etc. all insta-ban or lock your account if you come from a low reputation IP. These services make it impossible to participate online without giving big tech your identity. IMO they’re worse than everyone else combined because they play a critical role in helping all tech companies discriminate against people that want privacy.

Pretty much this.

Actually they ban your account and want you to upload ypur ID.

The weirdest thing was that Facebook a while ago had an onion adress too (presumably so that people from repressive regimes could access it). But if you'd use Tor to access them using the regular web: insta-ban.

Re: Check Your IP Reputation Score

#65
I did some testing on 35.214.66.222, it says this could be an attacker because it's on the wikimedia blocklist. But it's on the wikimedia blocklist because it's an IP block owned by google, and wikimedia doesn't want google creating accounts.

That doesn't make a website server from this IP an attacker!

Re: Check Your IP Reputation Score

#68
post #24

Earlier quoted context omitted.

no. Source: I work for IPinfo. We don't do "IP Reputation Score". We provide the attributes/insights related to an IP address, the user makes the decision of how to use that information.

I thought IPinfo was just sourced from Maxmind, am I wrong? Is there any way to know who are the original sources of info in this space and who are reselling?

All of our datasets at IPinfo, including geolocation, are proprietary and created in house - we're not reselling any 3rd party data.

Re: Check Your IP Reputation Score

#69
post #57

Earlier quoted context omitted.

Please stop making the world a worse place. Every online purchase I make comes from a datacenter IP with resistFingerprinting = true. I've got a good ISP that probably isn't selling surveillance about me, but websites themselves certainly abuse IP addresses (as you're doing here), and I see no reason to browse like some naive jamoke - datacenter IPs are easy to rotate, and fine-grained wireguard is already integrated…

What is the difference between the setup you describe being used for what I assume is privacy, and the same setup being used for nefarious reasons exiting from your presumably consumer level VPS?

The difference is as you just said - one is being used for privacy, and the other for "nefarious reasons".

It seems like you're trying to imply an association, while avoiding having to make the "if you have nothing to hide" argument explicitly.

Re: Check Your IP Reputation Score

#70

Earlier quoted context omitted.

"Fraudulent activity by bots" is a contradiction in terms that sounds like you've just mashed distinct issues together to create an emotionally manipulative phrase. Bots are bots, fraud is fraud. "Bots" are an overstated problem - websites should want to publish their information for every type of consumption. If serving some types of consumers causes too high of a load, then the inefficient code is what needs to be…

Bots here refers to automated traffic, and I don't think anyone on HN would be surprised by the assertion that most online fraud is automated.

I would reject that assertion, because it seems to tie a bunch of disparate issues in order to summarily "other" them. It probably makes for reassuring business metrics that are ultimately detached from reality. I'm sure my own browsing patterns are often miscatergorized into a bin of "look at how many bad guys we stopped", ultimately misleading businesses.

Please describe one specific trend/activity you're referencing, where an automated user agent specifically facilitates fraud, beyond merely facilitating users that just so happen to have fraudulent intent. Situations where augmented user agents are claimed to be prohibited via bullshit terms of service do not count.

Post reply on HN